9.8
CVSSv3

CVE-2018-19207

Published: 12/11/2018 Updated: 03/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin prior to 1.4.3 for WordPress allows remote malicious users to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

van-ons wp-gdpr-compliance

Github Repositories

Collection of WordPress Plugin PoC - For Educational Purposes ONLY

WordPress Plugin PoCs WordPress Plugin PoCs based on 1-Day WordPress Plugin Vulnerability ⚠️ Legal Disclaimer - Use At Your Own Risk ⚠️ This project is made for EDUCATIONAL and ETHICAL TESTING purposes ONLY Using of source code in this repository for attacking targets without prior mutual consent is ILLEGAL I take NO responsibility and/or liability for how you choose

cve-2018-19207

CVE-2018-19207 This is part of Cved: a tool to manage vulnerable docker containers Cved: githubcom/git-rep-src/cved Image source: githubcom/cved-sources/cve-2018-19207 Image author: githubcom/cved-sources/cve-2018-19207

Collection of WordPress Plugin PoC - For Educational Purposes ONLY

WordPress Plugin PoCs WordPress Plugin PoCs based on 1-Day WordPress Plugin Vulnerability ⚠️ Legal Disclaimer - Use At Your Own Risk ⚠️ This project is made for EDUCATIONAL and ETHICAL TESTING purposes ONLY Using of source code in this repository for attacking targets without prior mutual consent is ILLEGAL I take NO responsibility and/or liability for how you choose

Exploit of the privilege escalation vulnerability of the WordPress plugin "WP GDPR Compliance" by "Van Ons" (https://de.wordpress.org/plugins/wp-gdpr-compliance/) CVE-2018-19207

Exploit of Vulnerability CVE-2018-19207 in WP GDPR Compliance Plugin (WordPress) This python script creates a user with role admin Change the varbiables baseurl, username, email for your specific case A working email is needed, because an email is sent to this adress in order to setup a password for the newly created user account It works for WP GDPR Compliance plugin in ver